Cerberus is an Android banking trojan. The provided content describes it as a well-known malware family in cybercriminal communities that has been rented as a malware service and whose maintainer later auctioned the full project, including source code, APK/module, admin panel, servers, scripts, installation guidance, and customer contacts. ThreatFabric analysis cited in the content states Cerberus was not a clone of Anubis, despite emerging during a period when Anubis-based bankers were common.
High-confidence capabilities mentioned in the content include stealing SMS messages, sending SMS messages, obtaining the device contact list, collecting device information such as the default SMS app and device locale, stealing two-factor authentication codes, spoofing banking notifications to prompt credential entry, running installed apps, and using environmental and movement checks to avoid sandboxed or non-real devices. One mention also attributes keylogging and audio recording to Cerberus. The malware communicates with command-and-control infrastructure over HTTP.
The content consistently places Cerberus in the Android/mobile banking malware ecosystem and associates it with financial fraud, credential theft, interception of authentication codes, and unauthorized transactions. It is referenced as affecting home users and the finance sector, and as being reused or built upon by later Android banking trojans, especially Perseus, which multiple sources in the content say was built from leaked Cerberus source code. Additional campaign reporting in the content says Cerberus has been delivered via trojanized Android installers and via ClickFix/ErrTraffic payload chains targeting Android users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named crypto drainer active in 2024, associated with phishing-based theft of cryptocurrency via malicious smart contract approvals.
Older Android banking trojan whose leaked source code was used as the basis for Perseus.
Referenced as a previous Android threat family that Perseus builds upon.
Referenced as a predecessor Android banking trojan whose leaked source code was used in the development of Perseus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.